GoldDiggerPlus is a mobile malware family associated with GoldFactory, a Chinese-speaking financially motivated threat actor involved in banking-fraud operations. It is part of a broader cluster of GoldFactory tooling that includes GoldPickaxe, GoldDigger, and GoldKefu, and has been linked to campaigns targeting both Android and iOS devices.
GoldDiggerPlus is known primarily through its association with GoldFactory’s mobile fraud ecosystem rather than through extensive public technical detail on its own internals. GoldFactory has used social-engineering-driven mobile campaigns that impersonate trusted entities and distribute trojanized or fraudulent applications to compromise victims’ devices and facilitate financial theft. Across this ecosystem, the actor has targeted mobile banking users and abused device permissions and remote-control functionality to support on-device fraud, credential capture, and account takeover workflows.
The malware family has been referenced alongside other GoldFactory banking malware used against mobile users in Asia and elsewhere. GoldFactory operations have targeted banking customers and mobile users through deceptive application delivery and mobile-focused fraud techniques, with emphasis on harvesting sensitive information and enabling attacker-directed actions on infected devices. GoldDiggerPlus should therefore be understood as part of a coordinated mobile banking-malware portfolio used in financially motivated campaigns against smartphone users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It's attributed to GoldFactory, a Chinese-speaking threat actor linked to other banking malware families targeting both Android and iOS, such as GoldPickaxe, GoldDiggerPlus, and GoldKefu.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another banking malware family linked to GoldFactory and targeting mobile platforms.
Custom mobile malware family used by the GoldFactory cybercrime group; specific functionality not described in the provided excerpt.
Variant of the GoldDigger banking trojan, targeting mobile banking applications for credential theft and fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.